94563vdb entry
http://www.securityfocus.com/bid/94563 CVE-2015-1000010
HIGHNuclei
WordPress Simple Image Manipulator < 1.0 - Local File Inclusion
Record summary
CVE-2015-1000010 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
Remote file download in simple-image-manipulator v1.0 wordpress plugin
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryHIGHWordPress Simple Image Manipulator < 1.0 - Local File InclusionCVSS 7.5
WordPress Simple Image Manipulator 1.0 is vulnerable to local file inclusion in ./simple-image-manipulator/controller/download.php because no checks are made to authenticate users or sanitize input when determining file location.
Impact
An attacker can exploit this vulnerability to read arbitrary files on the server.
Remediation
Update to the latest version of the WordPress Simple Image Manipulator plugin.
WeaknessesCWE-284
AuthorsdhiyaneshDK
Template tagscve2015cvepacketstormwpscanwordpresswp-pluginlfiwpsimple-image-manipulator_projectvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:simple-image-manipulator_project:simple-image-manipulator:1.0:*:*:*:*:wordpress:*:*
https://packetstormsecurity.com/files/132962/WordPress-Simple-Image-Manipulator-1.0-File-Download.html https://wpscan.com/vulnerability/40e84e85-7176-4552-b021-6963d0396543 https://nvd.nist.gov/vuln/detail/CVE-2015-1000010 http://www.vapidlabs.com/advisory.php?v=147
Source: ProjectDiscovery
References
3vapidlabs.com
http://www.vapidlabs.com/advisory.php?v=147 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2015-1000010